ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Website Virus Removal
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

New Time-Based Defenses on GitHub and PyPI: What Sysadmins Must Know

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. New Time-Based Defenses on GitHub and PyPI: W...
  • All articles
  • Categories
  • Tags
  • Statuses

New Time-Based Defenses on GitHub and PyPI: What Sysadmins Must Know

Why Time Is Now a Security BarrierIn the ever-evolving landscape of cybersecurity, a new trend is emerging: using time itself as a defense mechanism....

Why Time Is Now a Security Barrier

In the ever-evolving landscape of cybersecurity, a new trend is emerging: using time itself as a defense mechanism. Recently, two major platforms in the software development ecosystem, GitHub and PyPI, have introduced changes that deliberately introduce delays in the update process. These measures aim to mitigate the risks associated with supply chain attacks, where malicious actors exploit the trust between developers and the dependencies they use.

Hourglass on server rack with padlocks representing time-based security

For system administrators and hosting companies in Spain, particularly those managing servers in regions like Catalonia (Barcelona, Lleida, Tarragona, Girona), understanding these changes is crucial. They directly impact how you handle software updates, security patches, and overall server protection.

Dependabot's 72-Hour Cooldown

GitHub's Dependabot, the automated dependency management tool, now waits 72 hours before opening a pull request for a new version update. This cooldown period does not apply to security updates, which remain immediate to address critical vulnerabilities. The rationale is to prevent projects from automatically adopting a version that has not yet undergone community scrutiny. This is particularly important in the context of server security, where a rushed update could introduce vulnerabilities or compromised code.

For teams that rely heavily on automation, this change means adjusting their workflow. The cooldown can be customized or disabled via the 'cooldown' option in the dependabot.yml file. This flexibility is essential for organizations with strict maintenance windows or their own validation processes. GitHub Enterprise Server will also incorporate this feature, with deployment planned for GHES 3.23.

PyPI's 14-Day Release File Restriction

PyPI, the central repository for Python packages, now rejects the upload of new files to a release if it was published more than 14 days ago. This measure targets a tactic known as 'version poisoning', where attackers compromise old, stable versions by uploading malicious artifacts with the same version number but different content. Such actions complicate audits and break fundamental assumptions in many build environments.

The change, integrated on July 8, 2026, follows a heated debate that resurfaced in March after compromises in projects like LiteLLM and Telnyx, linked to a mutable reference in the GitHub Action Trivy. PyPI acknowledges that the ecosystem lacks standardized semantics and APIs to declare whether a release is 'open' or 'closed', but anticipates improvements with initiatives like Upload 2.0 API and Staged Previews.

Implications for Server Security and Maintenance

For professionals responsible for server infrastructure, these changes underscore the importance of a proactive security posture. Here are some actionable steps to adapt:

  • Review your Dependabot configuration: Assess whether the default 72-hour cooldown fits your update cadence. If you need faster updates for non-security versions, consider adjusting the 'cooldown' setting, but weigh the risks.
  • Prioritize security updates: Even with the cooldown, security updates remain immediate. Ensure your monitoring systems flag these promptly and that your team responds without delay.
  • Strengthen dependency pinning: Use lockfiles and exact version pinning to reduce unexpected changes in your package graph. This minimizes the attack surface for malicious updates.
  • Plan PyPI releases carefully: If you are a package maintainer, ensure you publish all wheels and artifacts within the 14-day window. For new Python version support after that period, publish a new package version instead of modifying an old release.
  • Enforce strict CI/CD hygiene: Implement least-privilege permissions for tokens, rotate credentials regularly, and use anti-fraud controls to prevent a single compromise from leading to widespread damage.

Aligning with Broader Security Practices

These platform-level changes are not a silver bullet. They are part of a broader strategy that includes robust server protection, IP reputation management, and proactive threat blocking. For businesses in Spain, complying with GDPR and ensuring the security of customer data is paramount. Centralizing security measures, such as using tools that block malicious IPs and share threat intelligence across servers, can significantly enhance your defense posture.

At ALMC.es, we understand the complexities of managing secure server environments. Our approach integrates these latest developments into comprehensive security strategies, helping you stay ahead of threats while maintaining operational efficiency.

Conclusion

The introduction of time-based defenses on GitHub and PyPI marks a significant shift in how the developer community addresses supply chain attacks. By understanding and adapting to these changes, system administrators can better protect their infrastructure, reduce the risk of compromised dependencies, and ensure the integrity of their software supply chain. As the threat landscape evolves, so must our defenses—and sometimes, a little patience is the best security measure.

Related

  • Gitea Critical Flaw: Git Hooks Open Door to Server Takeover
  • Cisco FMC zero-day exploited: what sysadmins must do now
  • Coldcard Flaw: How Weak Seed Entropy Led to a $88M Bitcoin Heist
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Cloud Migration (AWS, Azure, Google Cloud)
Process Automation (Scripts and Bots)
Code Maintenance and Optimization
Monitoring & Incident Response (SIEM)
Backup & Disaster Recovery Plans
Relacionados
  • How to Harden Your Servers with Fail2ban and IP Reputation Feeds
    Cybersecurity · 1 day ago
  • Critical libssh2 flaw: urgent patch for SSH servers
    Cybersecurity · 1 day ago
  • Fail2ban: Your First Line of Defense Against Unauthorized Server Access
    Cybersecurity · 1 day ago
  • FortiBleed: Guarding Your Perimeter Against Credential Harvesting
    Cybersecurity · 1 day ago
  • Browser Extensions: A Hidden Supply-Chain Risk for Your Servers
    Cybersecurity · 1 day ago
  • Critical LoadMaster RCE: What Sysadmins Must Do Now
    Cybersecurity · 1 day ago
Servidores MCP Destacados
  • Desktop Commander MCP
    File System
  • Java Filesystem & Web MCP Server
    File System
  • Adspirer Ads Manager
    Productivity
  • NATS
    Communication
  • aml
    Database
  • OneNote MCP Server
    Productivity
  • PyPI Query MCP Server
    Development
  • Trade-MCP
    Development
  • PureScript MCP Server
    Development
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar